Описание
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
A flaw was found in the MongoDB database when requesting unexpected queries due to incorrect validation on the $external database. This flaw allows an attacker to cause a denial of service on the database or a server crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Out of support scope | ||
| Red Hat Openshift Data Foundation 4 | noobaa-core-container | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Not affected | ||
| Red Hat Satellite 6 | mongodb | Not affected | ||
| Red Hat Update Infrastructure 3 for Cloud Providers | mongodb | Will not fix |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
An authenticated user may trigger an invariant assertion during comman ...
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
6.5 Medium
CVSS3